Listen to this episode

Why You Should Pay Attention to the Oauth Hack

0:0022:07

Recorded March 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Erin opens this Petronella Technology Group podcast episode with reports that Russia may be laying the groundwork for cyber attacks on United States infrastructure, and Craig and BJ note evidence of scans against major energy companies and FBI findings that systems were scanned for software vulnerabilities. They argue that critical infrastructure often lags in adopting the best security tools and highlight layered defenses such as XDR and a 24/7 security operations center.

Craig then explains OAuth, the middleware that lets people log in to sites with Google or Facebook accounts, and the breach Microsoft reported. The group discusses the Lapsus$ hacking group's access to Microsoft and Okta systems, Okta's statement that approximately 2.5 percent of customers may have been impacted, and BJ's caution that initial breach pictures are not always accurate. They also touch on a ransomware attack on the Greek postal system, BJ's concern that state actors could exploit machine learning models in the financial sector to affect stock pricing, quantum computing advances, and crypto speculation. Craig closes with advice to create unique accounts, use multi-factor authentication, adopt zero trust, and consider burner emails.

Worth remembering

Key takeaways

  1. Craig advises logging in to websites where you used OAuth and changing your password, creating an account, or setting up a different email to mitigate the risk.
    “maybe create an account or set up a different email. That's secondary that's one way to mitigate the risk.”
  2. Craig says multi-factor authentication on all his accounts means a stolen username and password would still be stopped by another layer.
    “So I have multi-factor set up on all my properties. So even if they got the username password, they're going to get stopped by that layer.”
  3. Craig argues for a zero trust approach: create accounts directly, go through extra steps, and use unique credentials instead of relying on vendor logins.
    “I think we should move to more of a zero trust or a trustless, methodology where create an account on your own. Go through the extra hoops and layers, use a unique and password.”
  4. Craig recommends encrypting data even when using cloud services so that a breach at the provider only exposes an encrypted payload.
    “I always recommend that use encryption, even when using a cloud service, because at least if you encrypt your data in the cloud and hackers breach defenses of Microsoft, for example, then at least again, it's a layered approach, right?”
  5. Craig says XDR will not protect against everything but offers more effective detection of exploited weaknesses, paired with a 24/7 security operations center.
    “that's why like BJ was saying what the XDR, that's a nice layer. Not going to protect against everything, but at least it's more effective solution at detecting exploitation of some of these weaknesses and visibility.”
  6. BJ cautions that early breach figures, such as Okta's initial estimate affecting about 2.5 percent of customers, may not match the final findings.
    “we know just from how breaches work, that what the initial picture looks like is not always accurate”
  7. Craig argues machine learning code needs annual or quarterly review because buyers cannot know whether off-the-shelf products contain hidden back doors.
    “There needs to be annual or quarterly code review. The language that's chosen Python, for example, is popular at AI and ML.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

In this episode, the Petronella Technology Group team discusses what details are known about the breach of the Oauth firm used by Microsoft (among thousands of other clients), Okta, what the potential fall-out could be, and what YOU can do to protect yourself and your business.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.